VMware Workstation and Fusion contain a use-after-free vulnerability in the vbluetooth device. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host.
https://thecyberthrone.in/2024/05/14/vmware-fixes-vulnerabilities-exploited-in-pwn2own-vancouver/